On Sat, Dec 08, 2007 at 07:35:54PM -0500, Theodore Tso wrote:
Ok, yes, I'd forgotten we were chaining in the final sha_transform. I
plead too many bufs and buf+5s, which I fix up in 6/6. Funny thing is
that I'd convinced myself that this attack didn't work (correct) last
year when I read the paper I mentioned earlier. But yesterday and
today I couldn't spot the problem with it. So again, I'll add an
explicit comment for future hackers and researchers.
--
Mathematics is the supreme nostalgia of our time.
--